Skip to content
FIRERUN.

The BaaS & deploy-platform newsroom for builders

Subscribe

Firebase

Firebase Server Change Crashed iOS Apps, No Update Needed

A bad Firebase Analytics config payload crashed iOS apps on launch Sept. 28-29. Google says the fix is server-side, but the SDK still can't survive it.

Abstract flat-vector editorial illustration for "Firebase Server Change Crashed iOS Apps, No Update Needed"

A malformed response from a Google server crashed iOS apps that use Firebase Analytics, starting at 00:41 UTC on Sept. 29, 2026, and no app update caused it or can prevent a repeat. Google says it fixed the payload, but the SDK’s failure to handle bad input is the part developers still own (firebase-ios-sdk issue #16728).

What happened

The crash is an NSInvalidArgumentException: -[__NSDictionaryM setObject:forKeyedSubscript:]: key cannot be nil. According to the issue, it fires right after the Analytics SDK receives an HTTP 200 from its sdk-exp experiments endpoint and tries to process the response. Reporters said multiple already-shipped builds, including apps on Firebase SDK 12.14.0, began crashing at the same moment, which points away from client code. Crashes tended to hit on first launch, with later launches surviving, consistent with the SDK throttling its fetches.

A pinned reply from the Firebase team said Google “fully rolled out a fix” at 19:52 US/PDT on Sept. 28, which is 02:52 UTC on Sept. 29, about two hours after the crashes began. The team said no SDK update is required, but that some app instances may keep crashing for up to four hours after the rollout because of caching. Follow-up crash reports were filed as issues #16730 and #16731.

The reaction

Hacker News commenters split. Some pointed out that a server-side change should not be able to take down a client, and one noted there is still no sign of an SDK release that tolerates malformed input. Others said teams that bundle third-party SDKs accept this risk. Developer Gergely Orosz wrote on X that the SDK “started to crash ALL iOS apps that were using it.” That is his characterization; the Firebase team has not published a count of affected apps.

Our take

“No SDK update required” is accurate about the fix and dodges the cause. The server sent bad data once. The SDK turned it into a fatal crash on every affected device because it doesn’t validate the response. Until Firebase ships that hardening, any config-shaped payload from Google can do this again, and app developers have no way to catch it in testing.

What to do

  • Check Crashlytics for key cannot be nil spikes between 00:41 and about 07:00 UTC on Sept. 29. A crash alert in that window was probably this.
  • Don’t ship a hotfix for it. Nothing in your code changed.
  • If you don’t use Analytics experiments, consider whether that app needs the Analytics SDK at all, since the crash path runs through it.
  • Ask Firebase support to confirm a client-side fix is planned, and watch issue #16728 for it.

Stay in the loop

Get new articles in your inbox

We'll only email you when a new article drops. Unsubscribe anytime.